|
289991
|
- |
|
php-update
|
php-update
|
admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action.
|
NVD-CWE-Other
|
CVE-2006-6878
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289992
|
- |
|
php-update
|
php-update
|
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the …
|
NVD-CWE-Other
|
CVE-2006-6879
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289993
|
- |
|
php-update
|
php-update
|
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite,…
|
CWE-89
SQL Injection
|
CVE-2006-6880
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289994
|
- |
|
macromedia
|
shockwave
|
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute.
|
NVD-CWE-Other
|
CVE-2006-6885
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289995
|
- |
|
p-news
|
p-news
|
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a d…
|
NVD-CWE-Other
|
CVE-2006-6888
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289996
|
- |
|
freestyle
|
freestyle_wiki
|
FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for …
|
NVD-CWE-Other
|
CVE-2006-6889
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289997
|
- |
|
voc-project
|
voodoo_chat
|
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.
|
NVD-CWE-Other
|
CVE-2006-6890
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289998
|
- |
|
vz_forum
|
vz_forum
|
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a …
|
NVD-CWE-Other
|
CVE-2006-6891
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289999
|
- |
|
fersch
|
formbankserver
|
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ se…
|
NVD-CWE-Other
|
CVE-2006-6910
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290000
|
- |
|
digitizing_quote_and_ordering_system
|
digitizing_quote_and_ordering_system
|
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.
|
NVD-CWE-Other
|
CVE-2006-6911
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|